Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2022-3970

Опубликовано: 08 нояб. 2022
Источник: redhat
CVSS3: 8.8
EPSS Низкий

Описание

A vulnerability was found in LibTIFF. It has been classified as critical. This affects the function TIFFReadRGBATileExt of the file libtiff/tif_getimage.c. The manipulation leads to integer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The name of the patch is 227500897dfb07fb7d27f7aa570050e62617e3be. It is recommended to apply a patch to fix this issue. The identifier VDB-213549 was assigned to this vulnerability.

An integer overflow flaw was found in LibTIFF. This issue exists in the TIFFReadRGBATileExt function of the libtiff/tif_getimage.c file, and may lead to a buffer overflow.

Отчет

Red Hat Product security rated this issue having Moderate security impact as the exploitation of this issue will most likely to cause a denial of service attack. The score is based on the worst case scenario that an attacker might use the integer overflow to trigger other vulnerabilities such as buffer overflow, that could result in more adverse effects.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6libtiffOut of support scope
Red Hat Enterprise Linux 7compat-libtiff3Out of support scope
Red Hat Enterprise Linux 7libtiffOut of support scope
Red Hat Enterprise Linux 8compat-libtiff3Will not fix
Red Hat Enterprise Linux 8libtiffFixedRHSA-2023:288316.05.2023
Red Hat Enterprise Linux 9libtiffFixedRHSA-2023:234009.05.2023

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-680
https://bugzilla.redhat.com/show_bug.cgi?id=2148918libtiff: integer overflow in function TIFFReadRGBATileExt of the file

EPSS

Процентиль: 23%
0.00073
Низкий

8.8 High

CVSS3

Связанные уязвимости

CVSS3: 6.3
ubuntu
больше 2 лет назад

A vulnerability was found in LibTIFF. It has been classified as critical. This affects the function TIFFReadRGBATileExt of the file libtiff/tif_getimage.c. The manipulation leads to integer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The name of the patch is 227500897dfb07fb7d27f7aa570050e62617e3be. It is recommended to apply a patch to fix this issue. The identifier VDB-213549 was assigned to this vulnerability.

CVSS3: 6.3
nvd
больше 2 лет назад

A vulnerability was found in LibTIFF. It has been classified as critical. This affects the function TIFFReadRGBATileExt of the file libtiff/tif_getimage.c. The manipulation leads to integer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The name of the patch is 227500897dfb07fb7d27f7aa570050e62617e3be. It is recommended to apply a patch to fix this issue. The identifier VDB-213549 was assigned to this vulnerability.

CVSS3: 8.8
msrc
больше 2 лет назад

Описание отсутствует

CVSS3: 6.3
debian
больше 2 лет назад

A vulnerability was found in LibTIFF. It has been classified as critic ...

CVSS3: 9.8
redos
больше 2 лет назад

Уязвимость LibTIFF

EPSS

Процентиль: 23%
0.00073
Низкий

8.8 High

CVSS3